GPU VulnDB

Database/Firmware, BMC & network fabric

Supermicro BMC web interface (stack buffer overflow, X13SEDW-F): Second authenticated stack overflow in the BMC web

CVE-2025-8727Firmware, BMC & network fabriccurated

Impact

Second authenticated stack overflow in the BMC web function, giving full BMC compromise.

Who can reach it

Authenticated BMC web access with high privilege.

What to do

Flash the fixed Supermicro BMC firmware for the affected board SKU. BMC flash does not require a host reboot, but it does drop out-of-band management for several minutes per node - script it and stagger it so you never lose OOB across a whole rack at once. Check your exact MBD- part number against the advisory; Supermicro scopes these narrowly. Ships in the same November 2025 firmware batch as the other CoreWeave-reported findings.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.